Skip to content
LyraShield AIOpen beta

Open registration · Release assurance for AI-built apps

Know what was tested before you ship.

Turn an authorized target, retained evidence, and a fresh retest into one reviewable assurance record.

Passive public-surface check · No account required · Full platform open for registration

Live URL scan · passive and read-only

Check your public app before it ships.

Look for exposed secrets, missing browser protections, risky data-layer signals, and HTTPS issues. Results in seconds. No signup.

What the Lite Check covers and cannot prove

Release assurance for AI-built apps

Know what was tested before you ship.

Move from an authorized target to a reviewable assurance record without blurring detection, proof, and retest outcomes.

01 / Target

Define the authorized surface.

Name the target, scope, and permissions before any check begins. Coverage starts with an explicit boundary.

02 / Scan

Run checks that match the target.

Deterministic scanners and AI-assisted review remain separate coverage layers, never a universal guarantee.

03 / Evidence State

Keep detection separate from proof.

Results remain detected until independent verification exists. Retest-confirmed and inconclusive outcomes stay distinct.

  • Detected
  • Independently verified
  • Retest-confirmed
  • Inconclusive

04 / Fix Proposal

Prepare the change. Keep execution approval-bound.

A proposal can explain and stage a fix. PR execution remains blocked until a server-generated patch is bound to exact approval.

05 / Retest

Retest from a fresh server-owned scan.

Complete deterministic coverage can validate a clean retest. Engine-only absence remains inconclusive.

06 / Assurance Report

Ship the evidence record.

Coverage, findings, evidence states, retest outcomes, and limitations assemble into one reviewable report.

Scope stated · limitations retained

A result you can defend.

The full product keeps scope, coverage, evidence, fixes, and retests in one release record. Missing proof stays visible instead of becoming a silent pass.

Illustrative product preview · sample dataRELEASE / WEB-042

Assurance state

Review required

Two detected candidates still need independent evidence before this sample release can be treated as verified.

TARGET
authorized repo + URL
MODE
standard
REPORT
draft
RETEST
1 pending

Illustrative evidence ledger

Counts show product states, not production performance.

Detected
04
Independently verified
02
Retest-confirmed
01
Inconclusive
01

Vibe Security 50 registry

Machine checks and human evidence stay separate by design.

43
machine-testable
7
evidence-required
50
total controls
  1. 1Target
  2. 2Scan
  3. 3Evidence state
  4. 4Fix proposal
  5. 5Retest
  6. 6Assurance report

One record, three useful handoffs.

Builder

Make a launch decision.

See the highest-priority risks in plain language, what the scan could not prove, and what to do next.

Agency

Improve the client handoff.

Share an immutable executive or developer report without exposing repository coordinates or technical evidence.

Small team

Keep the review repeatable.

Use roles, audit history, schedules, notifications, GitHub checks, and approval-gated agent actions.

Bring assurance into the coding loop.

Compatible MCP clients can read findings, check launch readiness, start scans, and create reports. Mutating actions require explicit approval on the controlling terminal and fail closed when no terminal is available.

CursorClaude CodeWindsurfCodexOpenCodeAny compatible MCP client

Questions

What is release assurance for an AI-built app?

It is a review record that states which authorized checks ran, what they covered, the evidence behind each result, and what a retest established before a release ships.

Is this live today?

The passive Lite Check and five browser-local tools are public. The full release-assurance platform is live with open registration and remains in active development; subscribe for product updates.

What does a LyraShield result actually prove?

Only what the retained evidence supports. New scans distinguish detected candidates, independently verified findings, validated fixes, inconclusive retests, and checks that were limited or not applicable.

Does LyraShield open Fix PRs today?

Not yet. LyraShield creates approval-gated fix proposals, but PR execution stays blocked until the patch is generated server-side and bound to the exact approval.

Does it replace my existing tools?

No. SCA, secret scanning, URL checks, and repository review are coverage layers inside a wider assurance workflow. Specialist tools may still provide deeper coverage in their category.

What does it cost?

Pricing and plan boundaries will be announced as the open beta matures.

Get release assurance updates.

Stay in the loop on new evidence states, scan depth, and ways to share an honest assurance record.

We store your email for product updates and scorecard notifications. No sharing, no marketing blasts.